DNSSEC validation failing for NSEC signed zone with deeper wildcard

When testing on the zones linked below (in local knotd), and when asked for dig @127.0.0.1 -p 53 A shit.wildc.nsec.test.knot-resolver.cz +dnssec Resolver ends up servfailing because it can't validate proof of non-existence of wildc.nsec.test.knot-resolver.cz. DS record: